Hi Guys, Heres one for you. When you create the root certificate with openssl it is given a serial number of 0. Every other root signed certificate (peer certs) is given a serial number of 0X where X is the next certificate number e.g. 01. The certificates signed by root can be revoked and I have sucessfully done this. When I came to revoke the Root certificate Openssl ca says that teh serial number is invalid because it is one digit, that digit being 0, which is assigned to the root certificate by Openssl! Therefore I cannot successfully revoke the root certificate! Is there away to get Openssl to create the certificate with a 00 serial number or is there another way to revoke the root certificate. I am currently using: openssl ca -revoke cert.pem -config ca.cfg for revoking the cert. please HELP!!!!! cheers Evan Get your own zoom email - click here - http://www.zoom.co.uk/ ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]